PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSS
Kalir Brief · Item12 September 2026 · 07:12 UTC
BRIEFLeakhighP62

Leak of Yucatán, Mexico documents

Yucatán, México

Detected12 September 2026 · 07:12 UTC
Why it matters

A freshly posted thread (about 1 hour old) shares a pack of documents attributed to Yucatán, Mexico, promoted alongside Telegram channels whose names reference attacking governments. The exact record count and whether the files come from state/municipal entities are not yet confirmed, but the targeting pattern points to a government or public-sector source. Defenders in Mexican government and critical-infrastructure entities should treat this as a possible breach lead and monitor for reuse of the data.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score62
Detected12 September 2026 · 07:12 UTC
Related items6
Leak42
Base de datos de médicos del hospital Hermina Palembang (Indonesia) filtradaA fresh forum post advertises a database attributed to Doctors/Hermina Palembang, a hospital network in Indonesia, reportedly containing doctor/medical records. Healthcare data is highly sensitive and enables targeted fraud, phishing and extortion against staff and patients. Though outside the LATAM region, it reflects ongoing hospital-sector exposure worth tracking for regional analogues.
2h
Leak35
Base de datos de WiredBucks.com a la ventaA listing advertises a database from WiredBucks.com, a crypto-related service, suggesting stolen user or account records may be circulating. If genuine, the data could be used to target crypto users via credential reuse and phishing. Impact is modest given the site's size, but it is worth logging for correlation with larger credential campaigns.
3h
Leak55
Filtración de la base de datos de Success.com expuesta en foroA thread dated August 2026 announces a database leak from Success.com, a US media/education company, on a leak forum. The posting indicates a real organizational data set is circulating, likely containing subscriber or account data usable for credential stuffing and phishing. Defenders and brand-protection teams tied to the domain should confirm scope and force resets as needed.
3h
Leak48
Filtración de 43.773 cuentas de la app de pesca Lakemonster.comA breach of the fishing app Lakemonster.com exposed about 43,773 accounts including GPS locations, phone numbers and premium status. The combination of geolocation and contact data enables targeted phishing and physical-tracking risks for affected users. It is a real-company leak but outside the AR-LATAM critical-infrastructure scope, so it ranks lower.
4h
Leak58
Combolist de 100.000 credenciales argentinas publicadoA 100K high-quality combolist of Argentinian credentials was published, targeting accounts of a whole country rather than a single org. Such dumps fuel credential stuffing against local banks, government portals and telecoms, so AR defenders should force resets on exposed accounts. It is regionally relevant but dated months back, so treat it as context rather than a fresh alert.
4h
Leak30
Base de datos de Kerry T. Howe Surveying (Canadá) filtradaA database attributed to the Canadian surveying firm Kerry T. Howe Surveying Ltd has been offered for download on DarkForums. The victim is a small company, so scale is likely limited to client contact and project records. Low regional relevance, but it remains an org-specific leak usable for targeted follow-on attacks.
5h